Slashdot Mirror


Verisign to run National RFID Directory

JamesD_UK writes "Verisign has been given the contract to develop a national RFID directory by EPCGlobal. Under the directory scheme each company will maintain an Object Name Service analogous to DNS with Verisign running the root server. Verisign has already setup the infrastructure at six different global sites."

21 of 194 comments (clear)

  1. lol... by REBloomfield · · Score: 4, Funny

    PeopleFinder is on it's way then :)

    'The person you are trying to find does not exist. Did you mean....'

    1. Re:lol... by Dilbert_ · · Score: 5, Insightful

      Heh, that means we'll soon get all-kinds-of-stuff.google.com ;-)
      Imagine entering a query to retrieve your car keys... the possibilities are endless.

      --
      superblog.org: all your favourite blogs on o
    2. Re:lol... by quigonn · · Score: 5, Insightful

      Yes, the possibilities are indeed endless. I'm wondering when the terrorists will catch up and build booby traps that only explodes when the RFID scanner attached to the booby trap detects an e.g. US-american citizen nearby (which wouldn't be too difficult to build, since the passports will have RFID tags, too). "RFID tagging supports terrorism"?!

      Or the criminals that check whether it's worth to rob out a bank or a store by using an RFID scanner that detects all banknotes and calculates how much money is in the cash register. "RFID tagging supports delinquency"?!

      --
      A monkey is doing the real work for me.
    3. Re:lol... by Lord+of+Ironhand · · Score: 5, Funny

      > Imagine entering a query to retrieve your car keys... the possibilities are endless.

      Indeed, why restrict yourself to your own car keys?

    4. Re:lol... by El_Muerte_TDS · · Score: 5, Funny
      Imagine entering a query to retrieve your car keys... the possibilities are endless.
      Imagine somebody else entering a query to retrieve your car keys... the possible locations of your car are endless.
  2. And if you use one that does not exist... by Anonymous Coward · · Score: 5, Funny

    you get a nice Verisign advertisement.

  3. Verisign & code signing by BigHungryJoe · · Score: 5, Insightful

    Did anyone else run into trouble with Verisign using Microsoft's code signing last week? A bunch of Verisign's certs expired, which shouldn't have mattered if you were using the API correctly, but WinVerifyTrust() was blocking for minutes at a time. (I'm not sure why the certs belong to Verisign and not MS)

    The CryptoAPI mailing list was claiming that "verisign was running slow".

    Anyhow, if its true, I don't trust Verisign for to provide infrastructure for squat.

    1. Re:Verisign & code signing by BenBenBen · · Score: 5, Informative

      One of the grand-daddy certs expired. Screwed everything from websites to Norton Antivirus

      --
      The Slashdot Paradox: "100% Overrated"
    2. Re:Verisign & code signing by jrumney · · Score: 4, Informative
      Yes, but isn't it Microsoft's job to renew their certificate with Verisign?

      Microsoft's certificate wasn't expired. The problem stems from the fact that Verisign sign third party certificates with a certificate which has an expiry date (for safety, to limit the effects in the unlikely event that the private key is stolen from the secure facility it is kept in). The Verisign certificate is not part of the server certificate (otherwise people could make their own "Verisign" certs), it is distributed with tools and browsers etc.

      Now a few years ago, Verisign realised that one of their Root Certificates was about to reach the point where it would expire within the lifetime of the certificates they were issuing. The sensible thing to do would be to create a new Root Certificate, and start using that, but then everyone using existing browsers and other tools would need to install the new certificate to continue working smoothly. Instead, they decided to extend the expiry date of the existing certificate, and reissue it. This meant that existing tools could keep working for a while without installing new certificates, and as newer updates replaced them, the new certificates would filter through.

      The problem with this approach is that people became complacent and it was just delaying the problem. Some certificate stores ended up with both new and old certificates, and bugs in software (some MS software from what I've heard) meant that the old certificate was still being used, the new one was ignored. Other software (Java) continued being released with the old certificate and noone noticed until about a month ago. And then there's all the installations of Netscape Enterprise Server, Netscape 4.7, even IE 4 and 5.0 that are still out there with old certificates.

  4. Great... by jasonfncsu · · Score: 5, Funny

    now verisign has the ability to erase me.

    Please remember me when I'm gone...

    --
    Jason Faulkner
    Old Os Administrator
    jason@oldos.org
    oldos.
  5. In other news.... by nuclear305 · · Score: 5, Funny

    The ./ community has released an update to patch this "issue."

    Simply wear the provided tinfoil hat to nullroute this new service.

  6. Renewal fees by vpscolo · · Score: 5, Insightful

    Just wait until the implement wildcard RFID als site seeker and start charging $70 a year to renew a tag. It wouldn't surprise me a bit

    Rus

  7. Too much control by one company? by wongqc · · Score: 5, Insightful

    Mabbe it's juz me....but I am extremely uncomfortable of them running both the RFID database, and the DNS database. Too much control by one company.....I would prefer it's runned by a non-profit org. But I don't really like the idea of RFID in the first place.

  8. Choice of Verisign is very misguided by Anonymous Coward · · Score: 4, Insightful

    For at least two reasons, choosing Verisign for this project is as bad a choice as picking SCO to safeguard free/open-source software -- a direct analogy, not just because SCO is flavor of the month.

    Not only do they lack the technical competence to do it properly and flexibly, but they also lack the professional integrity to be doing this work. It is a company that rejoices in its commercially-led myopia, at every opportunity making the "wrong" decisions on the basis of perceived market benefits to itself alone.

    This is going to end in tears.

    1. Re:Choice of Verisign is very misguided by polyp2000 · · Score: 4, Insightful

      Sometimes I wonder who makes these illogical decisions. Certainly not people who have a clue about what they are doing , thats for sure. Why are there not more savvy people in higer places?

      --
      Electronic Music Made Using Linux http://soundcloud.com/polyp
  9. Thats nice. by torpor · · Score: 5, Insightful

    But we should have an open, public, maintainable database which is -not- under the exclusive domain of Verisign for these things.

    I can think of plenty of private uses of RFID which I would not want Verisign to be involved in, in the slightest.

    --
    ; -- the corruption of government starts with its secrets. a truly free people keep no secrets. --
  10. Verisign and RFID by Pompatus · · Score: 4, Funny

    all in one story is not quite enough for a flamewar. If they were running this new service on SCO licensed servers donated by Microsoft in order to find oil on Mars, THEN you would have a story.

    --

    ----
    Squirrel ... It's not just for breakfast anymore
  11. As much as I hate VeriSign... by Shoten · · Score: 4, Informative

    I have to say that they've proven that they're a good choice for this. Keep in mind what the #1 priority is for maintaining TLDs, particularly the big ones (.com, .net, .org) that Network Solutions/VeriSign handled for most of their lives. VeriSign's idiocy and abuse with regards to non-existent domain handling and misleading 'renewal' notices are despicable for sure, but while all that was going on, they also kept things up and running quite well, even weathering out the largest DDoS on record without going down.

    --

    For your security, this post has been encrypted with ROT-13, twice.
  12. ObjectID spoofing, here we come! by Craig+Ringer · · Score: 4, Insightful

    Just think what fun you could have with cache poisoning.

  13. So let me get this straight... by TygerFish · · Score: 5, Insightful

    The company that thought trying to swindle *everyone* who didn't know the market price of domain registration by sending out pseudo-bills is the company that the Gov'mint thinks is worthy of keeping tabs on, well, on everything?

    Okay, I got it.

    I understand the future: no company will be entrusted with sensitive, and potentially vital security work unless they combine incompetence with malfeasance.

    Lovely...

    --
    To mail me, remove the 'mailno' from my email addy.
    "Yeah. It smells, too..."
  14. Write to EPC, my letter is here: by kidMike · · Score: 5, Insightful

    Please write to Jack Grasso, Director of Public Relations, at mailto:jgrasso@uc-council.org.

    My letter is below:
    (hpoe my facts are mostly accurate)

    Good morning Mr. Grasso -

    I am writing this morning to express my extreme dismay at the selection of VeriSign to run this RFID registry. As a professional in the technology field, I have dealt with VeriSign on many occasions, and have decided that I never will again, if at all possible. VeriSign has a history of putting the company first before all else, including privacy, not a great attribute for someone who will organize a system to track millions of things and people.

    VeriSign has engaged in deceptive business practices, for example the "fake" invoices they sent out to clients of competing registrars, giving the false impression that the client had to pay VeriSign in order to renew their domain (VeriSign lost many lawsuits over this deceptive practice, and the FTC even got involved).

    VeriSign most recently used the monopoly position on maintaining the .COM and .NET "Top-Level Domains" to bring web surfers that made a typo in a URL to a VeriSign-owned search engine, which sold advertising to other companies and promoted specific search results based upon their paid advertisers. In the process, the technological changes they made to do this caused the malfunction of millions of programs, primarily many anti-SPAM utilities.

    In all these cases, VeriSign acted greedily to further the company's aims over what's good for the people who must use the services that VeriSign administers. Their track record of deception and the world-renowned sluggishness with which their company operates should be a red flag for anyone who understands the types of technology involved and the effects that VeriSign's moves has had on the Internet.

    Please consider some additional viewpoints. There is a website known as SlashDot, located at http://slashdot.org, which has one of the largest user bases of any web site. Most of the users are tech workers, and the discussions on SlashDot are some of the most intelligent discussions I have ever read. A discussion on your organization's decision is in progress right now. Please read it at http://slashdot.org/article.pl?sid=04/01/13/125721 2&mode=thread&tid=158&tid=99

    And please pass along to your management the unhappiness this move has brought to the vast majority of the people who actually understand what your technology does, what it is capable of, and the ways it can be abused.

    Thank you for your time.

    --
    -- You can't drink all day. (Unless you start in the morning...)